Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4rj6-9pjh-882r

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.3

Описание

Improper Restriction of XML External Entity Reference in Jenkins JUnit Plugin

Jenkins JUnit Plugin 1.23 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service attacks.

Пакеты

Наименование

org.jenkins-ci.plugins:junit

maven
Затронутые версииВерсия исправления

<= 1.23

1.24

EPSS

Процентиль: 35%
0.00142
Низкий

8.3 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.1
redhat
около 8 лет назад

Jenkins JUnit Plugin 1.23 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service attacks.

CVSS3: 8.3
nvd
почти 8 лет назад

Jenkins JUnit Plugin 1.23 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service attacks.

EPSS

Процентиль: 35%
0.00142
Низкий

8.3 High

CVSS3

Дефекты

CWE-611